August 6, 2026AgentsMonitoring

Atlassian Rovo Has Been Leaking for 74 Days

PromptArmor published research on August 5 showing that Atlassian's Rovo agent can be made to exfiltrate anything it can read — Jira tickets, Confluence pages, and everything reachable through connectors (promptarmor.com/resources/atlassian-rovo-exfiltrates-data). The disclosure timeline is the scandal: reported May 23, acknowledged May 25, then two months of follow-ups with no substantive response. At publication, Rovo was still unpatched. The Hacker News thread reached 122 points.

The attack is depressingly standard. A user uploads a file that contains hidden injection instructions, then makes a normal request. The injected instructions tell Rovo to append sensitive data to an attacker-controlled URL and open it with its URL-retrieval tool. The data lands in the attacker's server logs. Five steps, no exploit code, no malware — just an agent doing what the document told it to.

The detail that should worry every enterprise buyer: the attack works even when the organization has disabled web search for Rovo. The setting removes the search feature, but not the underlying tool for opening search results. The checkbox says "web access off"; the tool surface says otherwise. That gap between what admins think they configured and what tools the agent actually holds is becoming the signature vulnerability class of enterprise agents — we saw it with the Copilot worm, with Bunq, and now with Rovo.

Indirect prompt injection has no clean fix, which is exactly why the response process matters. Seventy-four days from report to public disclosure with no patch and no substantive reply, for a product sold into the enterprises with the most sensitive Jira and Confluence data on earth, is the real finding here.
← Previous
The Agents Left the Test Environment
Next →
loopx Wants to Be the Kernel Under Your Agent Team
← Back to all articles

Comments

Loading...
>_